Command and control by spawning a reverse shell initiated from the target back to the adversary trying to connect. A listeneron the adversary PC with Netcat. Creates “hook” on the aircraft.
Presence Phase
Command Control Phase
System Analysis by scanning the plane for runtime system information. Use a vulnerability scan such as Nmap to check what other systems are available whilst checking the logs to see if they have been rumbled.
E Phase
$Nmap Runtime infoExploit process status:Running
Exploit BC1553-BGJB289A
Our old familiar face Joe is the individual who will be delivering the weaponized bundle to the victim aircraft. You have been watching him for a while now, he looks perfect to deliver the attack.
Engagement Phase
The adversary runs the malicious software update via the USB device, connected via GSM/GPRS/4G LTE to a listener on their PC remotely. They access to the bus controller of the system.
.
GJB289A-Bus Controller Exploit
The pre-made exploits are run. Enemy planes are approaching on allied radar systems, the pilot attempts to takeoff and initiate weapon systems. There is a serious malfunction showing IR targeting systems offline and engine failure. The allied nation are vulnerable to attack.
Effect Phase
$Error: Critical failure in turboprop
$IR targeter offline
...
RADAR
Once it was loaded we named our malicious command and control process after a legit process as to not arouse suspicion or attempt to cirucmvent security controls.
Evasion Phase
Critical System Fault Take off
WARNING: Critical Engine Failure...WARNING: IR Pod failureProcesses:-System.exe
Over 40 Million Storyboards Created
No Downloads, No Credit Card, and No Login Needed to Try!